CREAM Lending Hack
What happened
CREAM Finance's Ethereum v1 lending markets were exploited on October 27, 2021 for about $130 million. The attack combined flash liquidity with manipulation of the yUSD vault share price that CREAM's collateral oracle relied on. The attacker made yUSD collateral appear more valuable, then borrowed most available v1 liquidity in one transaction.
CREAM's collateral pricing trusted a manipulable yUSD vault exchange rate, while uncapped recursive supply amplified the resulting collateral value. A direct transfer of underlying tokens to the vault changed pricePerShare and therefore the oracle value used by CREAM. Lending protocols must bound collateral from composable vault shares, use manipulation-resistant pricing, and constrain recursive supply paths that can magnify a transient valuation error.
Case & protocol details
Attack Timeline
The attacker used two controlled accounts and flash liquidity from MakerDAO and Aave. One account created yUSD and supplied it to CREAM, while the other used ETH collateral to borrow yUSD recursively and send it back, amplifying the first account's recorded crYUSD collateral. The attacker then withdrew Yearn 4-Curve tokens from the yUSD vault and transferred about $8 million of the underlying yCrv back to that vault.
That doubled yUSD's pricePerShare, and CREAM's hybrid oracle doubled the reported value of the collateral. The account could then borrow the remaining liquidity, repay the temporary loans, and retain the difference.
Security review history
- Trail of Bits Report
Evidence & learning
Sources and on-chain records
- report Post-mortem rekt.news
- report Post-mortem medium.com
- report Post-mortem medium.com
- transaction Transaction etherscan.io
- analysis Halborn CREAM Finance exploit analysis halborn.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.